Produced in association with SafeHorizon, the Horizon Europe project on detecting and disrupting crime-as-a-service, in which Scorechain is the blockchain-analytics partner.
A criminal can hold thousands of wallet addresses, and a fresh one costs nothing to generate. That is why chasing individual addresses rarely resolves a case. What resolves it is joining those addresses back together and attaching them to the entity that controls them. Wallet clustering and entity attribution are the two techniques that make that possible, and together they are how investigators turn a scatter of pseudonymous addresses into a named operation.
Wallet clustering is the process of grouping multiple blockchain addresses into a single unit based on evidence that one actor controls them all. It relies on behavioural and structural patterns in on-chain data, such as addresses spent together in one transaction, rather than any personal information. The result is a cluster: a set of addresses that behave as one wallet, which investigators can then trace and attribute as a unit.
Clustering is the first half of de-anonymization. On its own it does not name anyone; it establishes that a group of addresses share an owner. Entity attribution, covered further down, is the second half that connects that owner to a real-world identity.
A blockchain address is a pseudonym, not a name. It records that value moved, not who moved it, and one person or service can sit behind millions of addresses. That gap is what criminals exploit when they split funds across new addresses to look like unconnected parties.
Clustering closes the gap by treating control, not the address, as the unit of analysis. Once addresses are grouped by shared control, the number of addresses an actor uses stops being a defence, because the behaviour that links them survives every new address they generate.
Clustering is driven by heuristics, repeatable patterns that indicate shared control. Investigators rarely rely on one in isolation; the confidence comes from several pointing the same way. The main heuristics are:
No heuristic is infallible, which is why serious clustering combines them and records a confidence level rather than a binary claim.
The common input ownership (co-spend) heuristic: addresses spent together as inputs to one transaction are almost certainly controlled by the same actor.
Clustering method depends on the ledger model. Bitcoin and other UTXO chains lend themselves to co-spend analysis, because a single transaction can draw on many inputs and expose shared control directly. Account-based chains such as Ethereum work differently: value moves between persistent accounts rather than unspent outputs, so co-spend rarely applies. There, clustering leans on contract and administrative-key relationships, deposit-address reuse, and interaction patterns. The distinction matters because a criminal moving value across both models forces investigators to switch techniques mid-trace, which is where breadth of chain coverage becomes decisive.
Entity attribution is the step that assigns a real-world identity to a cluster. Clustering says a group of addresses share an owner; attribution says who that owner is, whether an exchange, a mixer, a sanctioned entity, or a named suspect. It combines the on-chain cluster with off-chain evidence: know-your-customer records, seizure data, court filings, and open-source intelligence.
Good attribution is disciplined about certainty. Analysts distinguish the operator who controls the keys from the beneficiary who holds funds through someone else's infrastructure, and they record a confidence level, high, moderate, or low, for every claim. The output lives in an attribution database with documented evidence and an audit trail, so a label can be defended later rather than merely asserted. That documentation is what separates an investigative lead from evidence that holds up under scrutiny.
Put together, clustering and attribution let an investigator start from one address, expand it into the full cluster the actor controls, and attach that cluster to an identity or a known service. A ransomware payment address becomes a window onto the operator's entire wallet, and the off-ramp where funds reach a regulated exchange becomes the point at which identity can be compelled.
Criminals push back with mixers, tumblers, and cross-chain bridges designed to break the links clustering depends on. These techniques raise the cost of attribution, but they leave their own patterns, and combining heuristics across chains often re-establishes the trail where a single heuristic fails. The practical goal is not certainty on every hop; it is a defensible chain of reasoning from the criminal wallet to a point of identification.
Clustering is probabilistic, and treating it as fact is a mistake. Heuristics can over-cluster, pulling unrelated addresses into one group, or under-cluster when an actor deliberately avoids co-spending. False positives carry real consequences when a label drives a compliance decision or an investigation, so confidence levels and documented evidence are not optional niceties. In court, attribution evidence is tested against admissibility standards, and an unexplained or black-box cluster is a weak foundation. Transparent, auditable methodology is what makes clustering usable as evidence rather than just intelligence.
Scorechain builds clustering and entity attribution into investigation tooling designed for institutional and law-enforcement environments. Scorechain Investigator groups addresses under a single controller through entity clustering and attribution, then matches those clusters against a database of more than 939,000 labelled on-chain entities, all on Scorechain's Digital Asset Intelligence graph. It takes an analyst from a single address to a complete, documented case.
The methodology is transparent by design. Investigator's risk score runs on a scale of 0 to 100 where a lower score signals higher risk, and it is auditable, so an analyst can see the reasoning behind a rating rather than trusting a black box, which matters directly for evidential weight. Flux Analysis visualises the fund flows and indirect exposure across protocols and chains that clustering surfaces, Wallet Screening checks an address and its cluster against the same labelled-entity database, and coverage across 25+ blockchains with 2,800+ VASP entries gives investigators the cross-chain reach that de-anonymization increasingly demands. Scorechain works alongside the wider blockchain-analytics field, including providers such as Chainalysis, Elliptic, and TRM Labs, as European-native infrastructure aligned with MiCA and AMLD6 and trusted by 350+ compliance and digital-asset teams.
This is also the on-chain layer Scorechain contributes to SafeHorizon, the Horizon Europe project working to detect and disrupt crime-as-a-service across the web, deep web, and darknet. As its blockchain-analytics partner, Scorechain provides the blockchain intelligence, transaction analysis, and investigation tools to trace cryptocurrency flows linked to cybercriminal activity, and clustering with entity attribution is where that work begins.
Pseudonymity was never anonymity. With disciplined clustering and well-documented attribution, a criminal's growing pile of addresses becomes the very thing that gives them away.
If your team is building crypto investigation or AML capability, book a Scorechain demo to see wallet clustering, entity attribution, and cross-chain tracing applied to your own cases.
Wallet clustering is the process of grouping multiple blockchain addresses into a single unit based on evidence that one actor controls them all, using behavioural and structural patterns in on-chain data rather than personal information. The result, a cluster, lets investigators trace and attribute many addresses as one wallet instead of chasing each address separately.
The common input ownership heuristic, also called co-spend, is the principle that when several addresses are used together as inputs to a single transaction, they are almost always controlled by the same actor. It is the foundation of clustering on Bitcoin and other UTXO-based blockchains, though it is combined with other heuristics to raise confidence.
Often, yes, though not from the blockchain alone. Clustering groups the addresses an actor controls, and entity attribution connects that cluster to a real-world identity using off-chain evidence such as KYC records, seizure data, and open-source intelligence. Identification is strongest at regulated off-ramps, where an exchange can compel identity.
Crypto wallets are pseudonymous, not anonymous. Addresses do not carry names, but every transaction is permanently recorded and openly queryable, so clustering and attribution can often trace funds and link addresses to an entity. Mixers and bridges raise the difficulty, but they leave patterns of their own.
Wallet clustering groups addresses that share a single controller; entity attribution names that controller. Clustering is a structural, on-chain step that says a set of addresses behave as one wallet. Attribution adds off-chain evidence to say who the wallet belongs to, with a documented confidence level. De-anonymization needs both.
On Bitcoin and other UTXO chains, clustering relies mainly on co-spend analysis, because one transaction can combine many inputs and expose shared control. Ethereum and other account-based chains move value between persistent accounts, so clustering leans instead on contract and administrative-key relationships, deposit-address reuse, and interaction patterns.































